Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

wpDataTables — Vulnerabilities & Security Advisories 10

Browse all 10 CVE security advisories affecting wpDataTables. AI-powered Chinese analysis, POCs, and references for each vulnerability.

wpDataTables is a WordPress plugin designed for creating and managing interactive data tables. Historically, it has been vulnerable to multiple security issues including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. The plugin has accumulated 10 CVEs, with several allowing unauthenticated attackers to execute arbitrary code or steal sensitive data. Notable characteristics include its extensive permissions system, which has been misconfigured in past versions, leading to unauthorized access. Security researchers have identified consistent patterns in its codebase that expose users to risks, particularly when improper input validation occurs. The plugin's widespread adoption makes it a frequent target for exploitation campaigns.

CVE IDTitleCVSSSeverityPublished
CVE-2026-5721 wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 6.5.0.4 - Unauthenticated Stored Cross-Site Scripting via CSV/Excel Data Import — wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts PluginCWE-79 4.7 Medium2026-04-20
CVE-2026-28039 WordPress wpDataTables plugin <= 6.5.0.1 - Local File Inclusion vulnerability — wpDataTablesCWE-98 7.5 High2026-03-05
CVE-2024-3820 wpDataTables - Tables & Table Charts (Premium) <= 6.3.1 - Unauthenticated SQL Injection — wpDataTables (Premium)CWE-89 10.0 Critical2024-06-01
CVE-2024-3821 wpDataTables - Tables & Table Charts (Premium) <= 6.3.2 - Missing Authorization to DataTable Access & Modification — wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts PluginCWE-862 7.3 High2024-06-01
CVE-2024-4895 wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 3.4.2.12 - Unauthenticated Stored Cross-Site Scripting via CSV Import — wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts PluginCWE-79 4.7 Medium2024-05-23
CVE-2024-0591 wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin <= 3.4.2.2 - Reflected Cross-Site Scripting. — wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts PluginCWE-79 6.1 Medium2024-03-13
CVE-2021-24200 wpDataTables < 3.4.2 - Blind SQL Injection via length Parameter — wpDataTables – Tables & Table ChartsCWE-89 6.5 -2021-04-12
CVE-2021-24199 wpDataTables < 3.4.2 - Blind SQL Injection via start Parameter — wpDataTables – Tables & Table ChartsCWE-89 6.5 -2021-04-12
CVE-2021-24198 wpDataTables < 3.4.2 - Improper Access Control leading to Table Data Deletion — wpDataTables – Tables & Table ChartsCWE-284 8.1 -2021-04-12
CVE-2021-24197 wpDataTables < 3.4.2 - Improper Access Control leading to Table Permission Takeover — wpDataTables – Tables & Table ChartsCWE-284 8.8 -2021-04-12

This page lists every published CVE security advisory associated with wpDataTables. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.